CVE- 2026-52912 is a high-severity use-after-free vulnerability located in the Linux kernel's netfilter nf_queue code, rated with a CVSS score of 7.8. Discovered by Nebula Security, the flaw allows local attackers to escalate privileges to root using publicly available proof-of-concept (PoC) exploit code. The vulnerability affects versions of the Linux kernel from March 2016 and has been fixed in several commits by May 2026.
No confirmed exploitations in the wild have been reported, but urgent patching is recommended to mitigate potential risks, especially for systems using bridge networking with NFQUEUE rules.